Nginx申请免费SSL证书配置Https

申请证书:

certbot命令申请免费的SSL证书并自动续期

配置SSL证书:

进行nginx.conf配置

1
2
3
4
5
6
7
8
9
10
#更改listen 80;为
listen 443 ssl;

#后面添加
ssl_certificate /etc/letsencrypt/live/inktea.xyz/fullchain.pem; #修改为fullchain.pem所在的路径
ssl_certificate_key /etc/letsencrypt/live/inktea.xyz/privkey.pem; #修改为privkey.pem所在的路径
ssl_session_timeout 5m;
ssl_ciphers ECDHE-RSA-AES128-GCM-SHA256:ECDHE:ECDH:AES:HIGH:!NULL:!aNULL:!MD5:!ADH:!RC4;
ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
ssl_prefer_server_ciphers on;

检查配置文件是否正确

nginx -t

然后重启nginx

nginx -s reload